Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2766▲ 12 respecto a la semana anterior
Críticas / altas1276▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
23.909 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.42% | — | Projectzealous PZ Frontend ManagerAI | 8/4/2026 | 24/7/2026 | El plugin PZ Frontend Manager para WordPress es vulnerable a la falta de autorización en todas las versiones hasta la 1.0.6 inclusive. La función pzfm_user_request_action_callback(), registrada a través del hook de acción wp_ajax_pzfm_user_request_action, carece tanto de comprobaciones de capacidad como de… | |
| Analizada | Alta (7.6) | 0.20% | — | Lfprojects MCP Java SDK | 7/4/2026 | 24/7/2026 | MCP Java SDK es el SDK oficial de Java para servidores y clientes de Model Context Protocol. Antes de la 1.0.0, el java-sdk contiene una vulnerabilidad de reenlace de DNS. Esta vulnerabilidad permite a un atacante acceder a un servidor MCP java-sdk local o privado de red a través del navegador de una víctima que es… | |
| Modificada | Alta (8.7) | 0.38% | — | Botan Project Botan | 7/4/2026 | 24/7/2026 | Botan es una biblioteca de criptografía C++. Antes de la versión 3.11.1, la implementación de TLS 1.3 permitía que los registros ApplicationData fueran procesados antes de que se recibiera el mensaje Finished. Un servidor que intenta aplicar la autenticación del cliente mediante certificados puede ser eludido por un… | |
| Modificada | Crítica (9.3) | 0.32% | — | Botan Project Botan | 7/4/2026 | 24/7/2026 | Botan es una biblioteca de criptografía C++. En 3.11.0, la función Certificate_Store::certificate_known tenía un nombre engañoso; devolvería verdadero si cualquier certificado en el almacén tuviera un DN (y un identificador de clave de sujeto, si está configurado) que coincidiera con el del argumento. No verificaba… | |
| Analizada | Alta (7.5) | 0.46% | — | Addressable Project Addressable | 7/4/2026 | 17/6/2026 | Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. From 2.3.0 to before 2.9.0, within the URI template implementation in Addressable, two classes of URI template generate regular expressions vulnerable to catastrophic backtracking. Templates using the *… | |
| Analizada | Media (6.5) | 0.35% | — | Pyload-ng Project Pyload-ng | 7/4/2026 | 17/6/2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the _safe_extractall() function in src/pyload/plugins/extractors/UnTar.py uses os.path.commonprefix() for its path traversal check, which performs character-level string comparison rather than path-level comparison. This… | |
| Analizada | Media (6.8) | 0.19% | — | Pyload-ng Project Pyload-ng | 7/4/2026 | 17/6/2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev97, the ADMIN_ONLY_CORE_OPTIONS authorization set in set_config_value() uses incorrect option names ssl_cert and ssl_key, while the actual configuration option names are ssl_certfile and ssl_keyfile. This name mismatch causes the… | |
| Analizada | Baja (2.7) | 0.36% | — | Djangoproject Django | 7/4/2026 | 17/6/2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new instances to be created via forged `POST` data. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be… | |
| Analizada | Crítica (9.8) | 0.60% | — | Djangoproject Django | 7/4/2026 | 17/6/2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInlineModelAdmin`. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be… | |
| Analizada | Alta (7.5) | 0.55% | — | Djangoproject Django | 7/4/2026 | 17/6/2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variants (with hyphens or with underscores) to a single version with underscores. Earlier, unsupported Django series (such as… | |
| Analizada | Alta (8.8) | 0.91% | — | Pyload-ng Project Pyload-ng | 7/4/2026 | 17/6/2026 | pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconnect scripts, SSL certs, proxy credentials) to admin-only access. However, this protection is only applied to core config… | |
| Analizada | Alta (7.5) | 0.85% | — | Djangoproject Django | 7/4/2026 | 17/6/2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. ASGI requests with a missing or understated `Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE` limit when reading `HttpRequest.body`, allowing remote attackers to load an unbounded request body into memory.… | |
| Analizada | Media (6.5) | 0.88% | 💥 PoC | Djangoproject Django | 7/4/2026 | 17/6/2026 | An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including excessive whitespace. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and… | |
| Analizada | Media (5.3) | 0.37% | — | Lfprojects Mlflow | 7/4/2026 | 17/6/2026 | MLflow is vulnerable to an authorization bypass affecting the AJAX endpoint used to download saved model artifacts. Due to missing access‑control validation, a user without permissions to a given experiment can directly query this endpoint and retrieve model artifacts they are not authorized to access. This issue… | |
| Analizada | Media (5.1) | 0.30% | — | Lfprojects Mlflow | 7/4/2026 | 17/6/2026 | MLflow is vulnerable to Stored Cross-Site Scripting (XSS) caused by unsafe parsing of YAML-based MLmodel artifacts in its web interface. An authenticated attacker can upload a malicious MLmodel file containing a payload that executes when another user views the artifact in the UI. This allows actions such as session… | |
| Modificada | Alta (8.7) | 0.74% | — | Tinyproxy Project Tinyproxy | 7/4/2026 | 10/8/2026 | Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer function uses strcmp to compare the header value against "chunked", even though RFC 7230 specifies that transfer-coding names are… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Online Hotel BookingAI | 7/4/2026 | 24/7/2026 | Se identificó una vulnerabilidad en code-projects Online Hotel Booking 1.0. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /booknow.php del componente Booking Endpoint. Tal manipulación del argumento roomname conduce a cross site scripting. Es posible lanzar el ataque de forma remota. El… | |
| Analizada | Alta (8.7) | 0.57% | — | Content Project Content | 6/4/2026 | 24/7/2026 | @hapi/content proporcionaba el análisis de los encabezados HTTP Content-*. Todas las versiones de @hapi/content hasta la 6.0.0 son vulnerables a la Denegación de Servicio por Expresiones Regulares (ReDoS) a través de valores de encabezado HTTP especialmente diseñados. Tres expresiones regulares utilizadas para… | |
| Analizada | Crítica (9.3) | 0.38% | — | Pyload-ng Project Pyload-ng | 6/4/2026 | 24/7/2026 | pyLoad es un gestor de descargas gratuito y de código abierto escrito en Python. En 0.5.0b3.dev96 y versiones anteriores, pyLoad tiene una vulnerabilidad de falsificación de petición del lado del servidor (SSRF). La solución para CVE-2026-33992 añadió validación de IP a BaseDownloader.download() que comprueba el… | |
| Analizada | Alta (7.7) | 0.36% | — | Pyload-ng Project Pyload-ng | 6/4/2026 | 24/7/2026 | pyLoad es un gestor de descargas gratuito y de código abierto escrito en Python. En 0.5.0b3.dev96 y versiones anteriores, la función API parse_urls en src/pyload/core/api/__init__.py obtiene URLs arbitrarias del lado del servidor a través de get_url(url) (pycurl) sin ninguna validación de URL, restricción de protocolo… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple IT Discussion ForumAI | 6/4/2026 | 24/7/2026 | Una vulnerabilidad ha sido encontrada en code-projects Simple IT Discussion Forum 1.0. Afectada por este problema es alguna funcionalidad desconocida del archivo /edit-category.php del componente Gestor de Parámetros. La manipulación del argumento cat_id conduce a inyección SQL. Es posible iniciar el ataque de forma… | |
| Aplazada | Media (5.5) | 0.51% | — | Code-projects Online FIR SystemAI | 6/4/2026 | 17/6/2026 | A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql of the component SQL Database Backup File Handler. The manipulation results in insecure storage of sensitive information. The attack may be performed from remote. The… | |
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Online FIR SystemAI | 6/4/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Online FIR System 1.0. Affected by this vulnerability is an unknown functionality of the file /Login/checklogin.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack is possible to be carried out… | |
| Modificada | Alta (7.5) | 0.65% | — | Go-jose Project Go-jose | 6/4/2026 | 18/9/2026 | Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWE) object will panic if the alg field… | |
| Analizada | Alta (7.5) | 0.39% | — | Distribution Project Distribution | 6/4/2026 | 17/6/2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, in pull-through cache mode, distribution discovers token auth endpoints by parsing WWW-Authenticate challenges returned by the configured upstream registry. The realm URL from a bearer challenge is used without validating… |